> ## Documentation Index
> Fetch the complete documentation index at: https://docs.methodfi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create MLE Public Key

export const ParamList = ({items = [], is_child = false}) => {
  return items.map(item => {
    const field_props = {
      id: Math.random().toString(),
      body: item.name,
      name: item.name,
      type: item.type,
      required: item.required
    };
    const enums = item.enums || [];
    const items = item.items || [];
    const has_items = items?.length > 0;
    const has_enums = enums?.length > 0;
    const should_default_open = item.defaultOpen || false;
    const render_child_item = () => {
      const child_props = {
        title: has_enums ? "Possible enum values" : "properties"
      };
      if (should_default_open) child_props.defaultOpen = true;
      const has_inline_enums = has_enums && enums.every(enum_item => typeof enum_item === 'string') && enums.map((enum_item, idx) => {
        const is_last = idx === enums.length - 1;
        const is_2nd_to_last = idx === enums.length - 2;
        return <>
            <code>{enum_item}</code>
            {is_last && ''}
            {is_2nd_to_last && ' or '}
            {!is_last && !is_2nd_to_last && ', '}
          </>;
      });
      const enum_list = has_enums && !has_inline_enums && <Accordion {...child_props}>
          {enums.map((enum_item, index) => <div key={`enum-${index}`}>
              <code>{enum_item.name}</code>
              <br />
              <p>{enum_item.description}</p>
            </div>)}
        </Accordion>;
      const item_list = has_items && <Expandable {...child_props}>
          <ParamList items={items || []} is_child />
        </Expandable>;
      return <>
          <p>
            {item.description}
            {has_inline_enums && [has_inline_enums.length > 1 ? ' One of ' : ' Must be ', ...has_inline_enums]}
          </p>

          {enum_list}
          {item_list}
        </>;
    };
    return is_child ? <ResponseField {...field_props}>{render_child_item()}</ResponseField> : <ParamField {...field_props}>{render_child_item()}</ParamField>;
  });
};

Creates a new public key registration for Message Level Encryption. You can register your key using either direct registration (providing the JWK directly) or well-known endpoint registration (providing a URL where Method can fetch your JWKS).

Both encryption keys (`use: "enc"`) and signing keys (`use: "sig"`) may be registered. Encryption keys are used to encrypt responses to you. Signing keys are used to verify the signature on your requests on the [signed MLE path](/2026-03-30/reference/message-level-encryption#signed-message-level-encryption).

<Note>
  Each key ID (`kid`) can only be registered once. Choose either direct or well-known registration for each unique key.
</Note>

## Body

<ParamList
  items={[
{
  name: "type",
  type: "string",
  required: true,
  description: "The type of key registration.",
  enums: ["direct", "well_known"],
},
{
  name: "contact",
  type: "string",
  required: true,
  description: "Contact email for the key registration.",
},
{
  name: "jwk",
  type: "object | null",
  required: false,
  description: "The JSON Web Key object. Required for direct registration, null for well-known.",
  items: [
    {
      name: "jwk.kid",
      type: "string",
      required: false,
      description: "Key ID. Method will assign one if not provided.",
    },
    {
      name: "jwk.kty",
      type: "string",
      required: true,
      description: "Key type. Must be 'RSA'.",
    },
    {
      name: "jwk.alg",
      type: "string",
      required: false,
      description: "Algorithm. If provided, it must match the key use: 'RSA-OAEP-256' for 'enc', 'RS256' for 'sig'. A mismatch is rejected with INVALID_JWK. If omitted, it is derived from the use.",
      enums: ["RSA-OAEP-256", "RS256"],
    },
    {
      name: "jwk.use",
      type: "string",
      required: false,
      description: "Key use. Defaults to 'enc'.",
      enums: ["enc", "sig"],
    },
    {
      name: "jwk.n",
      type: "string",
      required: true,
      description: "RSA modulus parameter.",
    },
    {
      name: "jwk.e",
      type: "string",
      required: true,
      description: "RSA exponent parameter.",
    },
    {
      name: "jwk.iat",
      type: "integer",
      required: false,
      description: "Key issue time, in seconds since epoch. Method uses the highest iat among in-window encryption keys to select the response encryption key on the signed MLE path.",
    },
    {
      name: "jwk.nbf",
      type: "integer",
      required: false,
      description: "Key not-valid-before time, in seconds since epoch. A key whose nbf is in the future is not selected.",
    },
    {
      name: "jwk.exp",
      type: "integer",
      required: false,
      description: "Key expiry time, in seconds since epoch. A key whose exp has passed is not selected.",
    },
  ],
},
{
  name: "well_known_endpoint",
  type: "string | null",
  required: false,
  description: "URL to your JWKS endpoint. Required for well-known registration, null for direct.",
},
]}
/>

## Well-Known Endpoint Requirements

If using `type: "well_known"`, your endpoint must return a JWKS that meets these requirements:

1. The document must have a top-level field named `keys` that has a list as its value.
2. Each JWK (an item in the list of `keys`) must be an object with a field named `kty` equal to `RSA`, a field `n` that is a valid string `n` for a JWK in accordance with the RFC, and a field `e` that is a valid string `e` for a JWK in accordance with the RFC.
3. Each JWK must have a field `kid` and it must be a string. Keys without a `kid` are dropped. On the standard MLE path, this value is what you pass as `cid` when making requests to Method.
4. `use` is optional and defaults to `enc`. Both `enc` and `sig` are accepted.
5. `alg` is optional. If present, it must match the `use`: `RSA-OAEP-256` for `enc`, and `RS256` for `sig`. A key whose `alg` does not match its `use` is dropped.
6. `iat`, `nbf`, and `exp` are optional numeric claims. Method preserves them and uses them for key selection and validity checks.

A single well-known endpoint can serve both your encryption key and your signing key. A team may also use direct registration and a well-known endpoint together, provided each `kid` is registered through only one of the two mechanisms, as described in the note above.

## Registering a Signing Key

The [signed MLE path](/2026-03-30/reference/message-level-encryption#signed-message-level-encryption) requires a signing key in addition to an encryption key. Register it with `use: "sig"` and `alg: "RS256"`:

<CodeGroup>
  ```bash cURL theme={null}
  curl https://production.methodfi.com/teams/mle/public_keys \
    -X POST \
    -H "Method-Version: 2026-03-30" \
    -H "Authorization: Bearer sk_WyZEWVfTcH7GqmPzUPk65Vjc" \
    -H "Content-Type: application/json" \
    -d '{
      "type": "direct",
      "contact": "security@yourcompany.com",
      "jwk": {
        "kid": "my-sig-key-2026",
        "kty": "RSA",
        "alg": "RS256",
        "use": "sig",
        "n": "p7K4R2Xb...M4a",
        "e": "AQAB",
        "iat": 1780309800,
        "nbf": 1780309800,
        "exp": 1811845800
      },
      "well_known_endpoint": null
    }'
  ```

  ```javascript Node.js theme={null}
  const key = await method.teams.mle.publicKeys.create({
    type: 'direct',
    contact: 'security@yourcompany.com',
    jwk: {
      kid: 'my-sig-key-2026',
      kty: 'RSA',
      alg: 'RS256',
      use: 'sig',
      n: 'p7K4R2Xb...M4a',
      e: 'AQAB',
      iat: 1780309800,
      nbf: 1780309800,
      exp: 1811845800
    },
    well_known_endpoint: null
  });
  ```

  ```python Python theme={null}
  key = method.teams.mle.public_keys.create({
    'type': 'direct',
    'contact': 'security@yourcompany.com',
    'jwk': {
      'kid': 'my-sig-key-2026',
      'kty': 'RSA',
      'alg': 'RS256',
      'use': 'sig',
      'n': 'p7K4R2Xb...M4a',
      'e': 'AQAB',
      'iat': 1780309800,
      'nbf': 1780309800,
      'exp': 1811845800
    },
    'well_known_endpoint': None
  })
  ```
</CodeGroup>

<Note>
  Register an `iat` on every encryption key if more than one will ever be active at a time: on the signed MLE path Method selects the response encryption key by the highest `iat` among in-window keys, and a tie with no `iat` fails with `MLE_ENCRYPTION_KEY_UNAVAILABLE`.
</Note>

## Returns

Returns the created public key registration object with an assigned ID and active status.

<RequestExample>
  ```bash cURL theme={null}
  curl https://production.methodfi.com/teams/mle/public_keys \
    -X POST \
    -H "Method-Version: 2026-03-30" \
    -H "Authorization: Bearer sk_WyZEWVfTcH7GqmPzUPk65Vjc" \
    -H "Content-Type: application/json" \
    -d '{
      "type": "direct",
      "contact": "security@yourcompany.com",
      "jwk": {
        "kid": "your-unique-key-id",
        "kty": "RSA",
        "alg": "RSA-OAEP-256",
        "use": "enc",
        "n": "s3C9N7Vz...J7c",
        "e": "AQAB",
        "iat": 1780309800,
        "nbf": 1780309800,
        "exp": 1811845800
      },
      "well_known_endpoint": null
    }'
  ```

  ```javascript Node.js theme={null}
  const key = await method.teams.mle.publicKeys.create({
    type: 'direct',
    contact: 'security@yourcompany.com',
    jwk: {
      kid: 'your-unique-key-id',
      kty: 'RSA',
      alg: 'RSA-OAEP-256',
      use: 'enc',
      n: 's3C9N7Vz...J7c',
      e: 'AQAB',
      iat: 1780309800,
      nbf: 1780309800,
      exp: 1811845800
    },
    well_known_endpoint: null
  });
  ```

  ```python Python theme={null}
  key = method.teams.mle.public_keys.create({
    'type': 'direct',
    'contact': 'security@yourcompany.com',
    'jwk': {
      'kid': 'your-unique-key-id',
      'kty': 'RSA',
      'alg': 'RSA-OAEP-256',
      'use': 'enc',
      'n': 's3C9N7Vz...J7c',
      'e': 'AQAB',
      'iat': 1780309800,
      'nbf': 1780309800,
      'exp': 1811845800
    },
    'well_known_endpoint': None
  })
  ```
</RequestExample>

<ResponseExample>
  ```json Response theme={null}
  {
    "success": true,
    "data": {
      "id": "team_jwk_12345", 
      "type": "direct",
      "jwk": {
        "kid": "your-unique-key-id", 
        "kty": "RSA",
        "alg": "RSA-OAEP-256",
        "use": "enc",
        "n": "s3C9N7Vz...J7c",
        "e": "AQAB",
        "iat": 1780309800,
        "nbf": 1780309800,
        "exp": 1811845800
      },
      "well_known_endpoint": null,
      "status": "active",
      "contact": "security@yourcompany.com",
      "created_at": "2026-06-01T10:30:00Z",
      "updated_at": "2026-06-01T10:30:00Z"
    },
    "message": null
  }
  ```
</ResponseExample>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.